news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-21404

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
6.3 Medium
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Risk score
50.4
Published
2026-06-04
Status
Published

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged WCF methods, enabling an attacker to write or overwrite files within application-defined paths.

Weaknesses

CWE-798

Coverage 1

vulnerability

NAVTOR NavBox

A critical vulnerability (CVE-2026-21404) has been identified in NAVTOR NavBox versions 4.16.1.20, allowing local attackers to gain unauthorized access due to hard-coded credentials within the Windows Communication Found…

CISA Advisories · Jun 4, 2026 Critical

Advisories and references